|
๐ฉ๐ช
Egon Bart
|
|
Cisco ASA SSL VPN bruteforcing/exploting
|
DDoS Attack
FTP Brute-Force
VPN IP
Port Scan
Hacking
Brute-Force
Exploited Host
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 31.13.195.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 31.13.195.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 11 23:48:29.069167 2023] [security2:error] [pid 1105678] [client 31.13.195.183:37846] [client 31.13.195.183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kupcakz.com"] [uri "/wp-content/plugins//hb-audio-gallery-lite/gallery/audio-download.php"] [unique_id "ZXfmHX1XI8fgOpEdY4LsSAAAAAQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฒ๐พ
Rizzy
|
|
Multiple WAF Violations
|
Brute-Force
Web App Attack
|
|
|
๐ฌ๐ง
Swiptly
|
|
WordPress xmlrpc spam or enumeration
...
|
Web Spam
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 31.13.195.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 31.13.195.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 10 10:56:19.740480 2023] [security2:error] [pid 30736] [client 31.13.195.183:50584] [client 31.13.195.183] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jessicabaer.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jessicabaer.com"] [uri "/cabaer-2023.sql"] [unique_id "ZXXfox1sS3it1MzPxRGjPAAAABM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
decisionconcepts
|
|
GX620: Fail2Ban detected 2 attempts against wordpress from: 31.13.195.183
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 31.13.195.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 31.13.195.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 08 18:37:52.312257 2023] [security2:error] [pid 16768] [client 31.13.195.183:37440] [client 31.13.195.183] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||statbotics.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "statbotics.com"] [uri "/2022-statbotics.sql"] [unique_id "ZXOo0LStdv2PmmOzKuoeGgAAAAY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฒ๐พ
Rizzy
|
|
Multiple WAF Violations
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
rsiddall
|
|
31.13.195.183 - - [06/Dec/2023:17:59:36 -0500] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5.0 ...
show more
31.13.195.183 - - [06/Dec/2023:17:59:36 -0500] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1.2 Safari/605.1.15"
31.13.195.183 - - [06/Dec/2023:17:59:36 -0500] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1.2 Safari/605.1.15"
...
show less
|
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 31.13.195.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 31.13.195.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 06 15:33:13.286540 2023] [security2:error] [pid 29237] [client 31.13.195.183:49002] [client 31.13.195.183] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||apeironsoft.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "apeironsoft.net"] [uri "/2022-eironsoft.sql"] [unique_id "ZXDaiegNK18fW2PAiucxdAAAACo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 31.13.195.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 31.13.195.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 05 12:17:18.421709 2023] [security2:error] [pid 16567:tid 47679020029696] [client 31.13.195.183:38518] [client 31.13.195.183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pcfinancial.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZW9bHhwcuwhP1dhmv8pMmwAAAIQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
Kreapptivo
|
|
[04/Dec/2023:16:37:51 +0100] Web-Request: "POST /wp-login.php", User-Agent: "-"
|
Bad Web Bot
Web App Attack
|
|
|
๐ง๐ช
holos.pt
|
|
Blocked for Directory Traversal (Requesting wp-config.php) in query string: ../wp-config.php
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 31.13.195.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 31.13.195.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 03 19:56:23.055100 2023] [security2:error] [pid 23500] [client 31.13.195.183:34852] [client 31.13.195.183] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||convtek.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "convtek.com"] [uri "/static/dump.sql"] [unique_id "ZW0jt5ruXar_ecUU7V9s9gAAAAA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ท
Kenshin869
|
|
Wordpress unauthorized access attempt
|
Brute-Force
|
|